Re: Domain users need access to local computer files

Tech-Archive recommends: Fix windows errors by optimizing your registry



You may use restricted groups in GPO to make them members of local administrators group.

If you have a few, it would be more simple to do it manually.

Don't mis choose the restricted group (you have two type), choose the "make member". The other empty the local admins group before adding yours.

as always, test your gpo in a test OU with test computer before

--
Cordialement,
Mathieu CHATEAU
http://lordoftheping.blogspot.com


"Jake" <jake44@xxxxxxxxx> wrote in message news:eRDTWi95HHA.5796@xxxxxxxxxxxxxxxxxxxxxxx
Mathieu CHATEAU skrev:
Hello,

For security reason, you shouldn't let them do this, but anyway it's not your question.

By default, users can't access other users's profile. You have two way:
Make their domain user account local administrator. That's not a real issue, they already have a local admin account.
Modify NTFS permission.

Hi,

Thanks for the tip.

How do I automate that a group of domain users should get local administrator rights...?

Jake

.



Relevant Pages

  • Re: Retriving Local admin Group mmebers name from AD domain PCs
    ... Is there a way to add a group from the domain to the local administrator ... You bind to the WinNT ... go through each of the members of this group. ... > - do an ADO query against the domain to retrieve all computer objects ...
    (microsoft.public.windows.server.scripting)
  • Re: Prevent user to install software
    ... Once they are made members of ... the local Administrator group they own the machine and can do what they ... "Cahya" wrote in message ...
    (microsoft.public.win2000.group_policy)
  • Re: Remove users from local groups
    ... Where did you apply the policy? ... At the domain level or OU level? ... domainname\Domain Users which are members of Users. ... has been made a local administrator is not being removed ...
    (microsoft.public.win2000.group_policy)
  • Re: Give user Admin rights to all PCs?
    ... With care you can use the GPO Restricted Groups to do this. ... CompAdmins) you create to be a member of Adminstrators ... restricted group for CompAdmins and use the Members ...
    (microsoft.public.windows.server.active_directory)
  • Re: Preventing Users from removing their PC from the Domain
    ... Steven L Umbach wrote: ... purpose and understand that Restricted Groups can remove all existing ... simply be removing the Restricted Group, Group Policy setting. ... you are logged on as a local administrator. ...
    (microsoft.public.win2000.security)